Skip to content

UnityPoint Health Affiliated

Disclosed Oct 2, 201312 years ago1,825 affectedConfirmed

Official notice

The covered entity (CE), UnityPoint Health, discovered that an office manager (from an independent private practice) was using physicians’ passwords to access patients’ protected health information (PHI). The types of PHI involved in the breach included names, social security numbers, addresses, driver’s license numbers, dates of birth, diagnoses, lab results, and medications affecting approximately 1,825 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and contacted the proper authorities to investigate any possible criminal infractions. The CE investigated the breach, which resulted in the office manager’s resignation from her job. The CE also retrained the physicians who shared their passwords with the office manager and obtained written assurances they would no longer share passwords. OCR obtained and reviewed the CE’s HIPAA compliance documentation.

What is known

People affected1,825 (as reported to HHS)
DisclosedOct 2, 2013
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 2, 20131,825
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UnityPoint Health Affiliated

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.